French Security Incident Response Team

FrSIRT   

      

   français French  anglais English

 
Vulnerability Notification Service
FrSIRT Partner Program
14-Day Free Trial
Contact FrSIRT Sales Dept.
 

Security Advisories
Linux Security Advisories
Virus and Threats Advisories
Latest Security News
Latest Zero Day Threats
Advisories and vulnerabilities by Vendor
Advisories and vulnerabilities by Keyword
 

Report a security incident
Report a new vulnerability
Security Mailinglist
 

Our Company
FrSIRT in the News
Advertise on FrSIRT.COM
Security Researchers and Exploit Writers Jobs
Contact Us

Mandriva Security Update Fixes E2fsprogs libext2fs Integer Overflow


Title : Mandriva Security Update Fixes E2fsprogs libext2fs Integer Overflow
Advisory ID : FrSIRT/ADV-2007-4151
CVE ID : CVE-2007-5497
Rated as : Low Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2007-12-11

Advisory Details

 
  Description
  Affected Products
  Solution
  References
Technical Description    Receive FrSIRT alerts in a Text format  Receive FrSIRT alerts in a PDF format  Receive FrSIRT alerts in an XML format  Receive FrSIRT notifications by SMS 

Multiple vulnerabilities have been idenitified in Mandriva, which could be exploited by attackers to cause a denial of service or execute arbitrary code [...]

Solution

Upgrade the affected packages :

Mandriva Linux 2007.0:
ff40ef940d3bbce7c4314d0bf06d529f 2007.0/i586/e2fsprogs-1.39-2.1mdv2007.0.i586.rpm
3159902d97bdc6871faec84838c9a5ab 2007.0/i586/libext2fs2-1.39-2.1mdv2007.0.i586.rpm
ec4e5539f5168aa045899458ec2b82c3 2007.0/i586/libext2fs2-devel-1.39-2.1mdv2007.0.i586.rpm
8cb48b6e43625f33f37554445f65f2f0 2007.0/SRPMS/e2fsprogs-1.39-2.1mdv2007.0.src.rpm

Mandriva Linux 2007.0/X86_64:
31ad9695ac03879d202ae8e1800e8df4 2007.0/x86_64/e2fsprogs-1.39-2.1mdv2007.0.x86_64.rpm
3fe3232e9f750d3855796e9ada2c7b18 2007.0/x86_64/lib64ext2fs2-1.39-2.1mdv2007.0.x86_64.rpm
cd1392e26b4c68be93c232cd991b0ef8 2007.0/x86_64/lib64ext2fs2-devel-1.39-2.1mdv2007.0.x86_64.rpm
8cb48b6e43625f33f37554445f65f2f0 2007.0/SRPMS/e2fsprogs-1.39-2.1mdv2007.0.src.rpm

Mandriva Linux 2007.1:
7d550dee8465b402dbc01e6881aa27a0 2007.1/i586/e2fsprogs-1.39-5.2mdv2007.1.i586.rpm
9f54587c0eb5b7af5241560bfee74b55 2007.1/i586/libext2fs2-1.39-5.2mdv2007.1.i586.rpm
4b30c50260a5d433c80e56800787c27c 2007.1/i586/libext2fs2-devel-1.39-5.2mdv2007.1.i586.rpm
3e4c659c9eaabf743382b604e2cb6fe4 2007.1/SRPMS/e2fsprogs-1.39-5.2mdv2007.1.src.rpm

Mandriva Linux 2007.1/X86_64:
82d1bd6787634b85c34ae44641f52a4f 2007.1/x86_64/e2fsprogs-1.39-5.2mdv2007.1.x86_64.rpm
26ef510b1e3b4fbcd0e27170908176c3 2007.1/x86_64/lib64ext2fs2-1.39-5.2mdv2007.1.x86_64.rpm
27a5dee786f11a543544f20a78811ce3 2007.1/x86_64/lib64ext2fs2-devel-1.39-5.2mdv2007.1.x86_64.rpm
3e4c659c9eaabf743382b604e2cb6fe4 2007.1/SRPMS/e2fsprogs-1.39-5.2mdv2007.1.src.rpm

Mandriva Linux 2008.0:
d4be99f5ff36d4d5ef62787611b626ff 2008.0/i586/e2fsprogs-1.40.2-5.1mdv2008.0.i586.rpm
2a7239249e195efd3b617061cdd0dcf7 2008.0/i586/libext2fs-devel-1.40.2-5.1mdv2008.0.i586.rpm
00c482bc1cf18b4a30968ad6a24b3d81 2008.0/i586/libext2fs2-1.40.2-5.1mdv2008.0.i586.rpm
1bc32b40c67ac660d97b9261e29a9b2c 2008.0/SRPMS/e2fsprogs-1.40.2-5.1mdv2008.0.src.rpm

Mandriva Linux 2008.0/X86_64:
e67a66424204013c42c54f8bd478d5ff 2008.0/x86_64/e2fsprogs-1.40.2-5.1mdv2008.0.x86_64.rpm
3a4b98d08dad0321199e981b8a1cd80a 2008.0/x86_64/lib64ext2fs-devel-1.40.2-5.1mdv2008.0.x86_64.rpm
af9c4dec36ca727fc1baba6a83766cb6 2008.0/x86_64/lib64ext2fs2-1.40.2-5.1mdv2008.0.x86_64.rpm
1bc32b40c67ac660d97b9261e29a9b2c 2008.0/SRPMS/e2fsprogs-1.40.2-5.1mdv2008.0.src.rpm

Corporate 3.0:
403bda3951bdca8b82113c0d0baabd2d corporate/3.0/i586/e2fsprogs-1.34-5.1.C30mdk.i586.rpm
d90ee27030d07a346a5237fe2938260f corporate/3.0/i586/libext2fs2-1.34-5.1.C30mdk.i586.rpm
7f3b1d7a825278d7288eb7c60282ed73 corporate/3.0/i586/libext2fs2-devel-1.34-5.1.C30mdk.i586.rpm
e7a4b7eac4f2b68ce7bd4707321fff69 corporate/3.0/SRPMS/e2fsprogs-1.34-5.1.C30mdk.src.rpm

Corporate 3.0/X86_64:
bed3787f200681b1b71920a47f3f8d74 corporate/3.0/x86_64/e2fsprogs-1.34-5.1.C30mdk.x86_64.rpm
1511236c38ef773820c2f45b9310b677 corporate/3.0/x86_64/lib64ext2fs2-1.34-5.1.C30mdk.x86_64.rpm
4d4d9749858131a86acbf27f61f9f9aa corporate/3.0/x86_64/lib64ext2fs2-devel-1.34-5.1.C30mdk.x86_64.rpm
e7a4b7eac4f2b68ce7bd4707321fff69 corporate/3.0/SRPMS/e2fsprogs-1.34-5.1.C30mdk.src.rpm

Corporate 4.0:
8cf5c9086da533ab006087e69d544c40 corporate/4.0/i586/e2fsprogs-1.38-3.2.20060mdk.i586.rpm
9e16d9df63f786c06c0fe41d0e9988f4 corporate/4.0/i586/libext2fs2-1.38-3.2.20060mdk.i586.rpm
8014e6c373d68a5a998586599ea4cd52 corporate/4.0/i586/libext2fs2-devel-1.38-3.2.20060mdk.i586.rpm
05a7b67cf7dcfcb587aec47f2d3f8493 corporate/4.0/SRPMS/e2fsprogs-1.38-3.2.20060mdk.src.rpm

Corporate 4.0/X86_64:
8b3b8a6ce94076b52978e43cf9e12f48 corporate/4.0/x86_64/e2fsprogs-1.38-3.2.20060mdk.x86_64.rpm
30b74422fda6bd3c157179613752a264 corporate/4.0/x86_64/lib64ext2fs2-1.38-3.2.20060mdk.x86_64.rpm
95784fca97d5fea9d54603b3f6b8a8cc corporate/4.0/x86_64/lib64ext2fs2-devel-1.38-3.2.20060mdk.x86_64.rpm
05a7b67cf7dcfcb587aec47f2d3f8493 corporate/4.0/SRPMS/e2fsprogs-1.38-3.2.20060mdk.src.rpm

Multi Network Firewall 2.0:
4d98c367af2d9f27df8d4b88a5afdf1f mnf/2.0/i586/e2fsprogs-1.34-5.1.M20mdk.i586.rpm
a952ade257bea9787ba8bc6f3fc71fd7 mnf/2.0/i586/libext2fs2-1.34-5.1.M20mdk.i586.rpm
bd6b983acf88cba046a86e1172e036a8 mnf/2.0/i586/libext2fs2-devel-1.34-5.1.M20mdk.i586.rpm
cad219a6351f58e7ae7299e894229a71 mnf/2.0/SRPMS/e2fsprogs-1.34-5.1.M20mdk.src.rpm

ChangeLog

2007-12-11 : Initial release

Vulnerability Management

Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.


 
 

Search

      

Mailinglist

    
 

Sun Solaris NFS RPC Zone Denial of Service Vulnerability

Sun Solaris NFS Kernel Module Local Denial of Service Vulnerability

Sun Solaris NFSv4 Client Kernel Module Denial of Service Vulnerability

Sun Java System Portal Server Cross Site Scripting Vulnerability

Sun rdesktop Code Execution and Denial of Service

Sun Java System Web Proxy Server Denial of Service Vulnerability

Sun Solaris "sendfilev()" System Call Denial of Service Vulnerability

Apple Mac OS X Code Execution and Security Bypass Vulnerabilities

Apple iPhone and iPod touch Multiple Code Execution Vulnerabilities

Apple Xcode Code Execution and Information Disclosure Vulnerabilities

Apple TV Data Processing Remote Code Execution Vulnerabilities

Apple Mac OS X Command Execution and Security Bypass Issues

Apple Safari for Mac OS X Remote Code Execution Vulnerability

Apple Mac OS X ARDAgent Local Privilege Escalation Vulnerability

Microsoft Visual Studio "Msmask32" Code Execution Vulnerability

Microsoft PowerPoint Command Execution Vulnerabilities (MS08-051)

Microsoft Windows Messenger Data Disclosure (MS08-050)

Microsoft Windows Event System Code Execution (MS08-049)

Microsoft Outlook and Mail Security Bypass Vulnerability (MS08-048)

Microsoft Windows IPsec Policy Data Disclosure Vulnerability (MS08-047)

Microsoft Windows MSCMS Code Execution Vulnerability (MS08-046)

Copyright 2003-2008 © FrSIRT.COM - Privacy Policy